CVE-2020-5355Incorrect Default Permissions in Dell Isilon Onefs

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 63.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21

Description

The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and stream forwarding. This provides the remotesupport user and users with restricted shells more access than is intended.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5dell/isilon_onefsunspecified8.2.2

🔴Vulnerability Details

2
GHSA
GHSA-w2f6-jgw8-wpp3: The Dell Isilon OneFS versions 82022-10-21
CVEList
CVE-2020-5355: The Dell Isilon OneFS versions 82022-10-21
CVE-2020-5355 — Incorrect Default Permissions in Dell | cvebase